25.01.2018 Views

white_paper_on_data_protection_in_india_171127_final_v2

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

may <strong>in</strong>strumentally be caused if the <strong>data</strong> is not adequately secured is significant.<br />

Understand<strong>in</strong>g which categories of <strong>data</strong> be c<strong>on</strong>sidered sensitive is a critical task.<br />

(iii) Difficulty <strong>in</strong> determ<strong>in</strong><strong>in</strong>g the c<strong>on</strong>text of use which could make <strong>data</strong> sensitive<br />

Although it may be possible to identify certa<strong>in</strong> types of <strong>in</strong>formati<strong>on</strong>, the process<strong>in</strong>g of which<br />

is more likely to cause harm to an <strong>in</strong>dividual; very often this is dependent not <strong>on</strong>ly <strong>on</strong> the<br />

nature of the <strong>in</strong>dividual, but also <strong>on</strong> the c<strong>on</strong>text <strong>in</strong> which it is used. For <strong>in</strong>stance, there may be<br />

certa<strong>in</strong> types of <strong>in</strong>formati<strong>on</strong>, which are not classified under the law, but it could become<br />

sensitive because of its potential impact <strong>on</strong> <strong>in</strong>dividuals if this <strong>data</strong> is compromised <strong>in</strong> any<br />

manner. This could <strong>in</strong>clude unique identificati<strong>on</strong> numbers, passport numbers, and computer<br />

passwords. The sensitivity of the <strong>data</strong> could also develop based <strong>on</strong> its comb<strong>in</strong>ati<strong>on</strong> with other<br />

types of <strong>in</strong>formati<strong>on</strong>. For example, an email address taken <strong>in</strong> isolati<strong>on</strong>, is not sensitive.<br />

However, if it is comb<strong>in</strong>ed with a password, then it could become sensitive as it opens access<br />

to many other websites and systems, which may expose the <strong>in</strong>dividual to harms such as<br />

cyber-attacks and phish<strong>in</strong>g frauds. 516 It is also possible that pers<strong>on</strong>al or even n<strong>on</strong>-pers<strong>on</strong>al<br />

<strong>data</strong>, when processed us<strong>in</strong>g big <strong>data</strong> analytics could be transformed <strong>in</strong>to sensitive pers<strong>on</strong>al<br />

<strong>data</strong>. Therefore, there may be a need to create safeguards which will prevent misuse of<br />

pers<strong>on</strong>al <strong>in</strong>formati<strong>on</strong> <strong>in</strong> these c<strong>on</strong>texts of use.<br />

6.3 Internati<strong>on</strong>al Practices<br />

European Uni<strong>on</strong><br />

The EU GDPR 517 provides separate rules for process<strong>in</strong>g of ―special categories of <strong>data</strong>‖, which<br />

are listed as pers<strong>on</strong>al <strong>data</strong> reveal<strong>in</strong>g racial or ethnic orig<strong>in</strong>, political op<strong>in</strong>i<strong>on</strong>s, religious or<br />

philosophical beliefs, trade-uni<strong>on</strong> membership, genetic <strong>data</strong>, biometric <strong>data</strong>, or <strong>data</strong> relat<strong>in</strong>g<br />

to the health, sex life and sexual orientati<strong>on</strong> of an <strong>in</strong>dividual. The EU GDPR provides that <strong>in</strong><br />

general, process<strong>in</strong>g of such <strong>in</strong>formati<strong>on</strong> is prohibited, except with the explicit c<strong>on</strong>sent of the<br />

<strong>data</strong> subject and where process<strong>in</strong>g is permitted <strong>in</strong> certa<strong>in</strong> specified situati<strong>on</strong>s as identified<br />

with<strong>in</strong> the law. 518<br />

United K<strong>in</strong>gdom<br />

Under UK DPA, ―sensitive pers<strong>on</strong>al <strong>data</strong>‖ <strong>in</strong>cludes those types of <strong>in</strong>formati<strong>on</strong> identified <strong>in</strong><br />

the EU GDPR. It also <strong>in</strong>cludes <strong>in</strong>formati<strong>on</strong> relat<strong>in</strong>g to the commissi<strong>on</strong> of an offence and<br />

proceed<strong>in</strong>gs relat<strong>in</strong>g to an offence. 519 The ICO guidel<strong>in</strong>es recognise that <strong>in</strong>formati<strong>on</strong> relat<strong>in</strong>g<br />

516 Lokke Moerel, ‗GDPR C<strong>on</strong>undrums: Process<strong>in</strong>g Special Categories of Data‘, IAPP (12 September 2016),<br />

available at: https://iapp.org/news/a/gdpr-c<strong>on</strong>undrums-process<strong>in</strong>g-special-categories-of-<strong>data</strong>/#, (last accessed 30<br />

October 2017).<br />

517 Regulati<strong>on</strong> (EU) 2016/679 of the European Parliament and of the Council <strong>on</strong> the protecti<strong>on</strong> of natural pers<strong>on</strong>s<br />

with regard to the process<strong>in</strong>g of pers<strong>on</strong>al <strong>data</strong> and <strong>on</strong> the free movement of such <strong>data</strong>.<br />

518 Articles 9 (1) and 9(2)(a)-(j), EU GDPR.<br />

519 Secti<strong>on</strong> 2, UK DPA.<br />

113

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!